Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17552FA3460943A3B40D3C2D126716B0BB7D1828ACB7B9B0A23F5D38C1FDBD55EE65A25 |
|
CONTENT
ssdeep
|
192:l4losINYccFc7THMruPfuoeRzSCc8Nmo64:l4losIqccC7THXPfuoUGz+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ca4beaeae848c8da |
|
VISUAL
aHash
|
fd000000ffffffff |
|
VISUAL
dHash
|
31e870320f232b2b |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
06000000007 |
|
VISUAL
cropResistant
|
0009411939610021,686c95a614152d0d,a2a2c6a623a2aaa2,12122723002b2b2a,0420c87869b2300c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.
Pages with identical visual appearance (based on perceptual hash)